T1021.001 Remote Desktop Protocol

Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.

Remote desktop is a common feature in operating systems. It allows a user to log into an interactive session with a system desktop graphical user interface on a remote system. Microsoft refers to its implementation of the Remote Desktop Protocol (RDP) as Remote Desktop Services (RDS).(Citation: TechNet Remote Desktop Services)

Adversaries may connect to a remote system over RDP/RDS to expand access if the service is enabled and allows access to accounts with known credentials. Adversaries will likely use Credential Access techniques to acquire credentials to use with RDP. Adversaries may also use RDP in conjunction with the Accessibility Features or Terminal Services DLL for Persistence.(Citation: Alperovitch Malware)

View in MITRE ATT&CK®

CIS Controls Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1021.001 Remote Desktop Protocol
Comments
Adversaries use RDP for lateral movement into privileged systems. Administrative enclave ACLs restrict RDP to explicitly authorized source and destination relationships, directly preventing arbitrary RDP access into or through the enclave.
References
CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure mitigates T1021.001 Remote Desktop Protocol
Comments
Adversaries use RDP for remote access or lateral movement into enterprise systems. RDP is inaccessible directly from external networks and reachable remotely only after authenticated VPN access through approved paths, directly preventing unauthenticated external RDP connectivity.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1021.001 Remote Desktop Protocol
Comments
Adversaries use RDP for remote access and lateral movement between systems. Segmentation and inter-zone ACLs permit RDP only across approved administrative paths, directly preventing unauthorized RDP connectivity between network zones.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1021.001 Remote Desktop Protocol
Comments
Remote Desktop access can be restricted through centrally managed authorization controls so that remote assets are permitted access only when they satisfy enterprise device-security and configuration requirements.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021.001 Remote Desktop Protocol
Comments
Using role-based access control (RBAC) to limit Remote Desktop Users group membership and Remote Desktop Protocol (RDP) permissions to users with a legitimate need can help prevent adversaries from using RDP for lateral movement.
References
CIS-6.4 Require MFA for Remote Network Access mitigates T1021.001 Remote Desktop Protocol
Comments
Enabling multi-factor authentication for remote logins helps minimize the adversary's ability to leverage stolen credentials.
References
CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021.001 Remote Desktop Protocol
Comments
Disabling Remote Desktop Services where RDP is not operationally required prevents adversaries from connecting through that service.
References
    CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021.001 Remote Desktop Protocol
    Comments
    Secure RDP configuration, gateways, TLS, and restricted administrative access reduce interception and direct exposure. RDP remains usable by an adversary who possesses authorized credentials or an active session.
    References
      CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021.001 Remote Desktop Protocol
      Comments
      Restricting TCP 3389 to approved management sources directly prevents unauthorized RDP connections and reduces RDP-based lateral movement.
      References
        CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1021.001 Remote Desktop Protocol
        Comments
        Restricting TCP 3389 to authorized management hosts directly limits unauthorized RDP access to servers.
        References
          CIS-16.8 Separate Production and Non-Production Systems mitigates T1021.001 Remote Desktop Protocol
          Comments
          Production/non-production segmentation can restrict RDP to explicitly approved administrative paths and block ordinary cross-environment RDP connectivity.
          References